OSVDB ID: 22385

Title: Mini-NUKE membership.asp Unauthenticated Password Modification

Info

Disclosure

Jan 12, 2006

Discovery

Unknown

Dates

Exploit

Jan 12, 2006

Solution

Unknown

Description

Mini-NUKE contains a flaw that allows a remote user to change any user's password without authenticating. This occurs when a remote attacker sends a specially crafted HTTP POST request to the 'membership.asp' script.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Miniex

Mini-NUKE

1.8.2

References

Credit

  • Mustafa Can Bjorn - nukedxnukedx.com - Personal Page


Direct URL: http://osvdb.org/22385